UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.150 Safari/537.36
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
UA: Mozilla/5.0 (Linux; Android 9; 5053K_EEA) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.152 Mobile Safari/537.36
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36
HKU\S-1-5-21-114268704-1918710269-250376416-1001\...\Run: [burcz] => explorer.exe hxxp://exinariuminix.info <==== UWAGA
HKU\S-1-5-21-114268704-1918710269-250376416-1001\...\MountPoints2: F - "F:\setup.exe"
HKU\S-1-5-21-114268704-1918710269-250376416-1001\...\MountPoints2: {47d8dce8-395f-11eb-8674-dcfe074bd22d} - "C:\Windows\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\autorun.exe /auto
Task: {BB9A5925-978E-4C64-8CB8-3BDFD70B59E8} - System32\Tasks\burcz => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v burcz /t REG_SZ /d "explorer.exe http://exinariuminix.info" <==== UWAGA
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]
CustomCLSID: HKU\S-1-5-21-114268704-1918710269-250376416-1001_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> "C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe" -ToastActivated => Brak pliku
FirewallRules: [TCP Query User{F85E41A3-98AF-41FB-8DD7-C1280A8C9E29}D:\programy\fifa 20\fifa20.exe] => (Allow) D:\programy\fifa 20\fifa20.exe => Brak pliku
FirewallRules: [UDP Query User{44DB664E-C356-480F-81BB-DAFF2ED6B779}D:\programy\fifa 20\fifa20.exe] => (Allow) D:\programy\fifa 20\fifa20.exe => Brak pliku
FirewallRules: [TCP Query User{75DDBF28-B218-42F9-ACA8-2C515F3D57C8}C:\users\burcz\appdata\local\temp\7zs5155\enterprisedu.exe] => (Allow) C:\users\burcz\appdata\local\temp\7zs5155\enterprisedu.exe => Brak pliku
FirewallRules: [UDP Query User{04941B44-B8F1-444A-8BE2-EA6335488257}C:\users\burcz\appdata\local\temp\7zs5155\enterprisedu.exe] => (Allow) C:\users\burcz\appdata\local\temp\7zs5155\enterprisedu.exe => Brak pliku
FirewallRules: [{353236E6-E446-4AD3-98FA-BDA3E6BF9E11}] => (Allow) C:\Users\burcz\AppData\Local\Temp\7zS27C6\HP.EasyStart.exe => Brak pliku
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0
UA: Mozilla/5.0 (Linux; Android 9; 5053K_EEA) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.152 Mobile Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot]